From b9d0884335324c797035458abc72c35d00bde3d9 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 3 Oct 2026 23:33:51 +0200 Subject: [PATCH] nextcloud: its handlers and tools run in the node's runtime (hq ADR 0198) The mesh-nextcloud container goes with its Dockerfile, build bases and bus credential. occ still runs through docker exec, now with the host's own docker CLI and socket. --- modules/nextcloud/Dockerfile | 40 ---------------------- modules/nextcloud/module.json | 62 ++++++++++------------------------- 2 files changed, 18 insertions(+), 84 deletions(-) delete mode 100644 modules/nextcloud/Dockerfile diff --git a/modules/nextcloud/Dockerfile b/modules/nextcloud/Dockerfile deleted file mode 100644 index d8a00e9..0000000 --- a/modules/nextcloud/Dockerfile +++ /dev/null @@ -1,40 +0,0 @@ -# nextcloud's runtime: the tool runtime, carrying this module's compiled code. -# -# **Built from this module's own directory and nothing else.** The sdk and the tool runtime are in -# the base images, published like any other artifact — which is what makes this buildable by the -# mesh from a repository and a path (novox/hq ADR 0069) rather than only on a workstation that -# happens to have the siblings. -# -# Two bases, named rather than pinned (novox/hq issue 044): the image this is COMPILED in and the -# image it RUNS in — the second must not carry a compiler. Declared in module.json's `build.on`. -ARG BUILD_BASE -ARG RUNTIME_BASE -ARG DOCKER_CLI - -# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder -# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM. -FROM ${DOCKER_CLI} AS dockercli - -FROM ${BUILD_BASE} AS build -# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own -# node_modules — the module is compiled against exactly the sdk it will run against. The compiler -# is invoked by its real path: node_modules/.bin entries are launcher symlinks the base image -# resolved away. -WORKDIR /app/modules/nextcloud -COPY . . -RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts \ - --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist - -FROM ${RUNTIME_BASE} -COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist -# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs -# the docker CLI itself present here, not only the socket. Copied from Docker's own official client -# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no -# systemd unit, no package manager tree pulled in for it). -COPY --from=dockercli /usr/local/bin/docker /usr/local/bin/docker -# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a -# provider's provisioner runs its reconcile loop in the same process, with the broker connected — -# the convention novox/hq issues 060/061 settled. A container that instead ran only its -# provisioner (`run`) served no tools and emitted no events; a container that named no command -# ran no provisioner at all. -ENV MESH_TOOL_MODULES=/app/modules/nextcloud/dist/index.js,/app/modules/nextcloud/dist/tools/index.js diff --git a/modules/nextcloud/module.json b/modules/nextcloud/module.json index 60260d0..fbcadd2 100644 --- a/modules/nextcloud/module.json +++ b/modules/nextcloud/module.json @@ -30,8 +30,7 @@ "share.created" ], "own-secrets": { - "admin": "${dir:state}/admin.secret", - "broker": "${dir:mesh-state}/broker" + "admin": "${dir:state}/admin.secret" }, "capabilities": [ "container-runtime" @@ -94,53 +93,28 @@ "mode": "0600", "content": "{}\n", "merge": "json" - }, - { - "id": "runtime", - "type": "container", - "name": "mesh-nextcloud", - "network": "host", - "volumes": [ - "${dir:mesh-state}/broker:/run/secrets/broker:ro", - "${dir:mesh-state}/config.json:/run/config/config.json:ro", - "${dir:state}/admin.secret:/run/secrets/admin:ro", - "/var/run/docker.sock:/var/run/docker.sock" - ], - "env": { - "MESH_BROKER_FILE": "/run/secrets/broker", - "MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}", - "MESH_NEXTCLOUD_CONFIG_FILE": "/run/config/config.json", - "MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin", - "MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "/run/secrets/admin" - }, - "restart-on": [ - "runtime-config" - ], - "artifact": "runtime" } ], "build": { - "on": [ - { - "arg": "BUILD_BASE", - "module": "mesh-tools", - "artifact": "build" - }, - { - "arg": "RUNTIME_BASE", - "module": "mesh-tools", - "artifact": "runtime" - }, - { - "arg": "DOCKER_CLI", - "image": "docker@sha256:018edbc908e08fcc9dbf029c812c34251e9b4719e6f71ca0e5eae2a987d014ca" - } - ], "artifacts": [ { - "name": "runtime", - "kind": "image", - "from": "Dockerfile" + "name": "code", + "kind": "bundle", + "language": "typescript", + "entrypoints": [ + "index.js", + "tools/index.js" + ], + "loads": [ + "index.js", + "tools/index.js" + ], + "env": { + "MESH_NEXTCLOUD_URL": "http://127.0.0.1:${port:80}", + "MESH_NEXTCLOUD_CONFIG_FILE": "${dir:mesh-state}/config.json", + "MESH_NEXTCLOUD_ADMIN_USER": "mesh-admin", + "MESH_NEXTCLOUD_ADMIN_PASSWORD_FILE": "${dir:state}/admin.secret" + } } ] }